Unsolved

This post is more than 5 years old

5178

February 3rd, 2005 08:00

virus? sp2 problem? -confused- and need help -please-

Ever since installing SP2 on my laptop, running WinXP, I've had quite a few problems. However, I uninstalled SP2 and reinstalled SP1 (because I was told by a few friends that it worked for them). Yeah - well - it didn't work for me. It didn't make anything worse, or better ... so, at the moment I have SP1 installed but can easily switch to SP2 if it's recommended. Whatever, almost anything at this point, I will do to fix my computer; I am really missing my laptop!! And every time I think I've got it fixed, something else wrong pops up.  I just can't take this anymore though. My laptop won't even sign online. Here, I have a cable modem and a laptop for convenience and comfort, and I can't even enjoy it.
 
Whenever I boot up my computer, it's always extremely slow once it finally reaches the point of showing my desktop. And when the hourglass finally goes away, I'm left with an error "Driver(Core) Not Found Winerr=2."
 
And, my HijackThis log is as follows:
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Updater.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\AOL Companion\companion.exe
C:\PROGRA~1\AVGANT~1\avgserv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Documents and Settings\All Users\Documents\AOL Downloads\Programs\Hijack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Shorten URL -
http://www.cjb.net/menuext.html
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AOL Instant Messenger\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O16 - DPF: ppctlcab -
http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=ff3132c1f1165ed87c5eb83386157f48ff902b60e6761397d62d367e7e25fc73023f21ef98dd5d11facc77917e4b6421e4b1f7feb4:b26d5d59881e3d3ce8ab2292e6aa4d79
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/ssoap/pptproactauthsmakamai/systemsoappro.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094274191968
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab
O16 - DPF: {886DDE35-E955-11D0-A707-000000521958} - http://69.56.176.78/webplugin.cab
O16 - DPF: {D03A1C33-1913-4533-A8C1-F2C8D13045DE} - http://www.cjb.net/search.cab

4.8K Posts

February 3rd, 2005 12:00

RSVPCeline,

Let's see what we can do...



Download L2mfix from one of these two locations:

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!



Download LSPFix and unzip to your desktop, then run it. Now, we need to:

1. check(tick) " I know what i'm doing".
2. click on (highlight) each occurance of the following, one at a time:

calsp.dll

3. then click " >>", moving each one, individually, to the 'Remove' pane.
4. (double-check, and make sure that only the above files are in the 'Remove'pane.)
5. click " Finish >>"



Post back the results of l2mfix.

-

Mike.

February 3rd, 2005 22:00

Sorry ... the 2nd URL on that reply isn't correct.
I forgot to change it, so, here are the two correct logs:
 

 
Initial Report:
 

 
Report After LSP-Fix:
 

 
Thanks so much trying to help me through this.
 
--Penny

February 3rd, 2005 22:00

I tried copying/pasting the logs from L2M-Fix, but everytime I did the forum gave me errors that my post was too long.  Would only allow me so many characters, etc. I tried cutting the post into two responses as well (the initial L2MFix report & then the L2MFix report after running LSP-Fix). Each post/response was still too large.  So, instead, I uploaded each log as a .txt file onto my AOL ftp space. Figured that'd be the easiest way, instead of trying to cut each response into even smaller and more multiple files.
 

 
Initial Report:
 

 
Report After LSP-Fix:
 

 
Thanks so much trying to help me through this.
 
--Penny

4.8K Posts

February 3rd, 2005 23:00

Penny,
 
Your more than welcome! I was hoping that scan would show me the dll(s) that I was looking for; let's try this...
 

First, let start off by looking where no-hijack has looked before:

1.  Downolad Dllcompare, and Killbox to your desktop.

2.  Run DLLCompare, then click "Run locate.com".

     When the scan is complete, you will see: Completed the scan, Click Compare to Continue

3. click "Compare".

    In a few minutes it be Completed


4. click "Make a Log of what was Found".

5. Post that back as a reply to this post.


Mike.

 

February 4th, 2005 05:00

here's the log from DLLCompare:

http://members.aol.com/rsvpceline550/comperrors/dllcomparereport1.txt


(Yes, it too is posted from my aol ftp because of it's length.

i hope this doesn't cause you problems.)

Thanks Again,

Penny

4.8K Posts

February 4th, 2005 15:00

Penny,
 
No, not at all. Actually I enjoy being able to look at the overall problem in more detail, rather than just in smaller, less informative pieces.
 
-
 
Ok, i've just ran that log through and didn't see that many hidden files, and none i'd recognize as belonging to the new VX2 problem.
 
So let's see if we can clean it off like this...
 


If you don't already have it, download, install and run AdAware SE Personal.
 
-
 
Next, check for, and download any available updates:
 
1.  click " Check for updates now".
2.  Click " Connect".
3.  If updates(definitions) are available click " Ok", otherwise, click " Ok".
4.  Click " Finish".
 
-
 
Next, configure AdAware to be as effective as possible:
 
1.  Click the ' gear' in the upper-right hand corner of the AdAware Window.
2.  Click Scanning, and check(tick) the following:
   
    Scan within archives
   Scan active processes
   Scan registry
   Deep-scan registry
   Scan my IE Favorites for banned URLs
   Scan my Hosts file

   
3.  Click " Tweak".
4.  Click " Scanning Engine", then check(tick) the following:
    Unload recognized proceses & modules during scan
5.  Click " Cleaning Engine", then check(tick) then following:
   > Always try to unload modules before deletion
   During removal, unload Explorer and IE if necessary
   Let Winodws remove files in use at next reboot
   Delete quarantined objects after retoring
6.  Then click " Proceed"
 
-
 
Now, let AdAware locate and remove anything it finds, by:
1.  Click " Start".
2.  Check(tick) " perform full system scan".
3.  Click " Next".
 
-
 
Exit the program.
 


If you don't already have it, let's go to Lavasoft's VX2 Cleaner web-page, and follow the instructions to download and install the utility.
 
-
 
Next, run AdAware SE Personal, then:
 
1.  Click " Add-Ons".
2.  Double-click " VX2 Cleaner"
3.  Click " Ok", to " Execute this tool".
4.  If nothing is found, click " Ok", then exit the program.
 
   (or)
 
4.  If VX2 has been found on your system, click " Clean System"
5.  Then when it's complelely done, reboot your computer.
6.  Repeat steps 1-4 again.
 
Be sure to follow any instructions it might give while using it.
 


Run HiJackThis and click " Scan", then check(tick) the following, if present:
 

F0 - system.ini: Shell=
 
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
 
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=ff3132c1f1165ed87c5eb83386157f48ff902b60e6761397d62d367e7e25fc73023f21ef98dd5d11facc77917e4b6421e4b1f7feb4:b26d5d59881e3d3ce8ab2292e6aa4d79
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab
O16 - DPF: {886DDE35-E955-11D0-A707-000000521958} - http://69.56.176.78/webplugin.cab
O16 - DPF: {D03A1C33-1913-4533-A8C1-F2C8D13045DE} - http://www.cjb.net/search.cab
 

Now, with all windows closed except HiJackThis, click " Fix checked".
 


Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
files...
 
    c:\windows\system32\calsp.dll
 
-
 
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
 


Go to www.kaspersky.com, then:
 
1.  Click " Online virus scanner"
2.  Click " Browse", then browse to, then doubleclick on the following file(s), one at a time:
 
  C:\Updater.exe
 
3.  Click " Submit"
4.  Post back the results.

 

Does AdAware report seeing a VX2 problem? Post back a new log along with the results of the above scans.
 
-
 
Mike.
 

4.8K Posts

February 4th, 2005 16:00

Penny,

Before you delete c:\windows\system32\calsp.dll let me make sure that it's been completely removed from windows sockets, otherwise removing it will 'break' your internet connection. If that happens, just use LSPFix to fix the calsp.dll entry that i'd posted earlier.

Post back another HiJackThis log before you continue with my last post.
 
-
 
Mike.
 

February 6th, 2005 06:00

Mike ---
 
Okay, I think I should have mentioned this in the beginning - don't know why I didn't - but, I am unable to connect to the internet via my laptop. The entire time I have been posting, and running programs and providing logs and such ... I have been using my friend's desktop computer and moving files onto/from my laptop via USB reader. Therefore, I've been able to do every step, but run that online virus scan.
 
I have a wireless card, cable internet connection, and modem available on my laptop ... and used to use them all, intermittenly depending on my location ... but now, can't seem to access any of them. In the "clock-area"/"startup" of my taskbar, my volume icon doesn't even load anymore.
 
I also have the problem on my computer, of not being able to access my taskbar/start menu. When I boot up my laptop, the mouse works everywhere on the desktop, but when hovering over the taskbar or trying to use the start menu, I constantly receive an hourglass.
 

 
Here's my laptop's task manager:
 

 
And also, here's the latest HiJackThis log:
 
Logfile of HijackThis v1.99.0
Scan saved at 9:27:52 PM, on 2/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\AVGANT~1\avgserv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\All Users\Documents\Tutorial - Fixing Laptop (Forum Help)\2005-02-02 - (Prog-A0) - HiJackThis! v1.99\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AOL Instant Messenger\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/ssoap/pptproactauthsmakamai/systemsoappro.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094274191968
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG6 Service - GRISOFT s.r.o - C:\PROGRA~1\AVGANT~1\avgserv.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ulead Burning Helper - Unknown - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 

 
Thanks again,
Penny
 

4.8K Posts

February 6th, 2005 12:00

Penny,
 
Is this something that happened just recently? Or is it something that has been going on for awhile? Did it happen after installing, or running something?
 
-
 
Have you tried using:
 
sfc   /scannow
 
from a command prompt just to see if any system files are missing or corrupt for some reason?
 
-
 
Mike.
 

February 8th, 2005 13:00

Mike --

Well, it started a couple months ago - but I had to spend some time in the hospital so I haven't had a chance to start working to fix it until now.

I have taken all the steps you've given. In the process ... I even learned about 'slipstreaming' (which I'd never heard of before).  And just to calm my nerves ... (haha - fighting with my laptop can get to me sometimes) ... I attempted to create my own WinXP SP2 bootable CD. And voila ... it worked. But anyway, enough of that ... back to business. =)

I still can't get online. Sometimes, especially with wireless internet, it shows I'm connected, and at an excellet speed; however, I am unable to access the internet. I've tried installing different versions of AOL, to see if that was messing with my dial-up modem perhaps. And I'm still having no luck.  Everything else seems fine ... the computer loads well, and there are no more problems with my taskbar/start menu freezing.

Here's the latest HijackThis log:

Logfile of HijackThis v1.98.0
Scan saved at 12:27:35 AM, on 2/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVGANT~1\avgserv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\All Users\Documents\AOL Downloads\Programs\Hijack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Registry Repair Pro] C:\Program Files\Windows Registry Repair Pro\Windows Registry Repair Pro.exe -X
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Shorten URL -
http://www.cjb.net/menuext.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AOL Instant Messenger\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab -
http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/ssoap/pptproactauthsmakamai/systemsoappro.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094274191968
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
 

4.8K Posts

February 8th, 2005 19:00

Penny,

Sorry to hear about your hospital stay - I hope everything is ok. We're good on the log! ... now we just need to figure out what's wrong with your wireless setup. You mentioned having a modem on that system? Does the dialup work and let you connect to the internet ok, just not the wireless adapter?

-

Mike.

 

No Events found!

Top